Executive Summary

Aceville Pte Ltd is a Singapore-registered company that functions as the international legal wrapper for Tencent Cloud. Through a single RDAP NIC handle (APA7-AP โ€” "ACEVILLE PTELTD administrator"), it registers IP blocks that appear to be located in 10 different countries while all routing through AS132203 in Singapore. Our honeypot has tracked 181 IPs on this infrastructure, of which 156 carry abuse scores โ‰ฅ80 and 59 are classified "malicious" by GreyNoise. This is not a hosting provider with an abuse problem. This is a jurisdictional arbitrage architecture.

The Corporate Shell

Aceville Pte Ltd appears in exactly one public context that connects it directly to Tencent: the Hong Kong Trade Development Council Belt and Road portal. The HKTDC service-provider listing for Aceville does not describe an independent company. It describes Tencent Cloud โ€” attributing to Aceville the same data-center infrastructure, the same product lines, the same "leading cloud provider in China" narrative that Tencent uses in its own materials.

The entity exists for one purpose: to hold IP registrations in APNIC's Singapore jurisdiction, creating a legal buffer between Chinese cloud infrastructure and international reporting mechanisms.

The Numbers

MetricValueSignificance
Total tracked IPs181On AS132203 (Tencent) in our honeypot
Aceville-registered15485% of Tencent traffic via SG shell
Abuse score โ‰ฅ 8015686% of all IPs flagged as abusive
GreyNoise "malicious"5933% confirmed mass-scanning
AbuseIPDB score = 10022Maximum abuse confidence
Average threat score53.5Significantly above global mean (~30)
Claimed countries10SG, US, JP, HK, BR, DE, ID, TH, IN, KR
Actual BGP routing1 (SG)ALL traffic routes through Singapore

The Geo-Discrepancy Architecture

This is the signature of the wrapper. Every IP registered to Aceville exhibits the same pattern:

  • RDAP country: Varies (US, JP, SG, DE, HK, BR, ID, IN, KR, TH)
  • BGP routing (Cymru): Always SG
  • Abuse country: Matches RDAP claim (the fiction propagates)

The effect: when a victim in the US receives an SSH brute-force from 43.166.137.151, every database says "US". AbuseIPDB says US. MaxMind says US. Only BGP routing analysis reveals the truth โ€” this is a Singaporean-routed Chinese cloud instance pretending to be American.

IPThreatClaimsRoutes ThroughRDAP Org
43.128.237.224100JPSGIRT-ACEVILLEPTELTD-SG
124.156.202.242100SG/INSGIRT-ACEVILLEPTELTD-SG
43.166.137.15198USSGIRT-ACEVILLEPTELTD-SG
43.173.69.14793US/SGSGACEVILLE PTE.LTD.
43.133.148.17089SG/IDSGIRT-ACEVILLEPTELTD-SG
43.156.212.8688SGSGIRT-ACEVILLEPTELTD-SG
101.32.248.9488SGSGIRT-ACEVILLEPTELTD-SG
43.155.239.18388SG/KRSGIRT-ACEVILLEPTELTD-SG
43.157.98.11882DESGIRT-ACEVILLEPTELTD-SG
43.167.157.24070JP/SGSGACEVILLE PTE.LTD.

The NIC Handle: APA7-AP

A single RDAP entity โ€” NIC handle APA7-AP, name "ACEVILLE PTELTD administrator" โ€” controls 146 IP allocations visible in our database. This administrator contact is the sole technical reference for all Aceville-registered blocks across APNIC.

The handle format is standard APNIC: "APA" (Aceville Pte administrator) + "7" (sequential) + "-AP" (Asia-Pacific region). What's unusual is the scale: 146+ netblocks managed through a single administrative contact with no published abuse-handling team, no NOC contact, no network operations presence distinct from the parent Tencent infrastructure.

The Tencent Connection

What we can document

  • AS132203 is named "TENCENT-NET-AP-CN - Tencent Building, Kejizhongyi Avenue, CN"
  • HKTDC Belt and Road portal lists Aceville as providing Tencent Cloud services
  • PeeringDB lists AS132203 as "Tencent Global" with 1000 IPv4 prefixes
  • Tencent Cloud's international product (tencentcloud.com) serves from the same IP ranges
  • All Aceville IPs route through Tencent's Singapore POP

What this means

Aceville is not a customer of Tencent. Aceville is Tencent โ€” the international face that holds registrations in a jurisdiction where Chinese cybersecurity law doesn't apply and where Singaporean regulators have neither mandate nor resources to police cloud abuse originating from 181 IPs spread across 10 claimed countries.

The Abuse Reporting Dead End

Consider the practical effect. A security researcher detects SSH brute-forcing from 43.166.137.151. They look up the IP:

  • GeoIP: United States
  • AbuseIPDB: Country = US, ISP = "Aceville Pte Ltd"
  • Abuse contact: Points to an APNIC handle in Singapore

Where do they report? The US has no jurisdiction (the IP doesn't physically exist there). Singapore's PDPC regulates data privacy, not network abuse. China's CERT handles domestic networks only. The traffic routes through SG but claims US residency. There is no entity with both jurisdiction and enforcement capability.

This is the wrapper's function. Not to hide the infrastructure โ€” it's easily discoverable โ€” but to ensure that discovery leads nowhere actionable.

Exposed Services

Shodan data for the high-threat Aceville IPs reveals:

IPThreatOpen PortsNotable
43.128.237.22410080HTTP server (C2 panel?)
124.156.202.2421005000Custom service (non-standard)
43.173.69.1479380, 443Web server (credential harvesting?)
43.133.148.1708980, 443, 3008, 8080Multi-service deployment
43.155.239.18388443, 3306Exposed MySQL + HTTPS
43.163.107.1548322, 443, 3000SSH + Grafana/Gitea port

The presence of non-standard ports (3008, 5000, 3000) combined with maximum threat scores suggests these are purpose-built attack infrastructure โ€” not legitimate services with a security problem.

Scale in Context

181 Tencent/Aceville IPs in honeypot
86% Abuse score โ‰ฅ 80
10 "Countries" (all route SG)
1 Actual routing point

The Pattern

This is not unique to Tencent. It's a template used by every major Chinese cloud provider expanding internationally:

  • BytePlus (TikTok/ByteDance) โ†’ Singapore shell โ†’ AS150436 โ†’ 45+ malicious IPs
  • UCloud โ†’ "UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED" โ†’ AS135377 โ†’ 124+ IPs
  • Yisu Cloud โ†’ Hong Kong shell โ†’ AS138152/142403 โ†’ 28+ IPs, bulletproof designation
  • CDS Global Cloud โ†’ US registration, Chinese tech contact โ†’ AS63199 โ†’ 4 IPs ALL at 95-100

The Cloud Silk Road series will trace each of these threads. This first letter establishes the archetype. Aceville is not an outlier โ€” it's the most visible instance of the most common Chinese cloud internationalization pattern.

Implications

For defenders

GeoIP databases are weaponized against you. An IP claiming "US" that routes through SG on a Chinese ASN is not American infrastructure. BGP-path analysis is the only reliable geographic indicator for Aceville ranges. Treat 43.x.x.x blocks on AS132203 as Chinese cloud regardless of claimed location.

For regulators

The wrapper model exploits the gap between registration jurisdiction (Singapore), routing jurisdiction (Singapore), claimed location (varies), and enforcement jurisdiction (nowhere). No single authority has both the mandate and the capability to act on abuse from these ranges.

For researchers

The RDAP handle APA7-AP is a single point of attribution for 146+ netblocks. Track this handle โ€” it grows quarterly as Tencent expands international capacity under the Aceville wrapper.

Methodology: Data from SSH honeypot (Cowrie) observation over 30 days, enriched via AbuseIPDB, GreyNoise, Shodan InternetDB, RDAP/WHOIS, BGP routing (Team Cymru), and PeeringDB. Threat scores computed from multi-source aggregation. Geo-discrepancy detected by comparing RDAP-registered country against BGP announcement origin. Investigation cross-references existing dossiers TI-2026-028 (Shell Companies) and TI-2026-032 (Aceville/Tencent).
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Cloud Silk Road โ€” 1 / 10 Next โ†’